Vulnerabilities > CVE-2022-31057 - Unspecified vulnerability in Shopware
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subject to an authenticated Stored XSS in Administration. Users are advised to upgrade. There are no known workarounds for this issue.
Vulnerable Configurations
References
- https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2022
- https://docs.shopware.com/en/shopware-5-en/security-updates/security-update-06-2022
- https://github.com/shopware/shopware/commit/3e025a0a3e123f4108082645b1ced6fb548f7b6f
- https://github.com/shopware/shopware/commit/3e025a0a3e123f4108082645b1ced6fb548f7b6f
- https://github.com/shopware/shopware/security/advisories/GHSA-q754-vwc4-p6qj
- https://github.com/shopware/shopware/security/advisories/GHSA-q754-vwc4-p6qj
- https://packagist.org/packages/shopware/shopware
- https://packagist.org/packages/shopware/shopware